Job offer

Senior Lead, Technology Risk & Controls - SOX / DOIC Programs

The position of Senior Lead for Technology Risk & Controls at Northern Trust in Chicago (hybrid) involves overseeing SOX and DOIC IT controls and leading a team of eight specialists. The role requires at least 15 years of experience in technology risk management and responsibility for ensuring compliance across more than 200 systems in on-premises and cloud environments.

Job description

You will join the Technology Risk and Controls team in a remote/on-site role to oversee the Technology SOX and DOIC IT control and monitoring process in a global banking environment. This role is responsible for ensuring SOX compliance of IT General Controls (ITGC), maintaining and testing key controls for over 200 systems in on-premises and cloud environments, supporting internal audits, and proactively identifying risks and recommending corrective actions. As a Senior Leader in Technology Controls, you will drive audit responsiveness, coach and mentor a team of specialists, and help continuously strengthen cybersecurity, data resilience, and overall governance readiness.

Tasks

  • Serve as the senior escalation point for Enterprise Governance ITGC controls (OGGC), including access management, risk and security compliance, change management, infrastructure and environment controls (ECS), SOX 2000 reporting to IT&E, First Compliance, automated management, compliance programs, and cybersecurity.
  • Lead and collaborate with business units and project teams to ensure the consistent, efficient, and risk-aware implementation of critical ITGC controls, including penetration testing, security assessments, vulnerability management, and disaster recovery.
  • Develop and implement technology risk frameworks across IT components, with a focus on identifying risk indicators, ensuring continuous monitoring, and enabling robust, data-driven risk mitigation and compliance assurance.
  • Senior Lead – Overseeing a team of 8 SOX and ITGC control owners/coordinators, managing their performance, career development, morale, and long-term succession planning.
  • Prepare monthly, quarterly, and annual Executive ITGC Compliance reports for senior leadership, including key metrics, control maturity trends, risk focus areas, and the status of corrective actions.
  • Collaborate with internal audit, external auditors, and regulatory authorities to support successful SOX certifications, IT audit responses, and regulatory audits, and to ensure audit efficiency, accuracy, and evidence-based assurances.
  • Collaborate with global technology providers, application owners, and control owners to identify, assess, and remediate critical gaps in application controls and technology infrastructure in real time.
  • Develop and maintain ITGC training and continuing education programs, including in-depth workshops on key areas of ITGC such as access controls, change management, infrastructure controls, and data security.
  • Present the performance of ITGC controls, risk trends, and audit findings on a quarterly and annual basis to the C-suite, the Technology Committee, and key governance bodies to drive data-driven decisions and targeted risk mitigation.
  • Analyze and document the costs of controls and the risk of noncompliance across all ITGC areas, striking a balance between compliance rigor and operational agility.
  • Support ITGC-compliant key performance indicators, budgeting, and strategic roadmap alignment to ensure that investments in controls align with the bank’s digital transformation imperatives.

Requirements

  • Bachelor's degree in computer science, information systems, cybersecurity, finance, accounting, or a related field.
  • At least 15 years of experience in technology risk management and IT controls

Job details

© 2025 House of Skills by skillaware. All rights reserved.
Our website uses cookies to make navigation easier for you and to analyze the use of the site. You can find more information in our privacy policy.